Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

esp-idf — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in esp-idf, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumerations (CWEs) related to the esp-idf software framework developed by Espressif Systems. The vulnerability database specifically targets weaknesses found within the ESP32 family of microcontrollers and their associated development environments, capturing a wide spectrum of security flaws ranging from buffer overflows and memory corruption issues to improper access control mechanisms and insecure default configurations. This collection covers public disclosures and advisories issued over the last several years, ensuring that users have access to a historical view of how the software’s security posture has evolved in response to emerging threats and internal audits. By utilizing this resource, security professionals and developers can effectively track vendor advisories from Espressif Systems to stay informed about critical patches and workarounds. Furthermore, the page serves as an educational tool for understanding specific weakness classes within the context of embedded IoT systems, allowing for deeper analysis of common failure modes in real-time operating systems. Users can also look up the specific vulnerability history of the esp-idf product to identify recurring patterns or legacy issues that may impact long-term system stability and security compliance. This centralized view simplifies the process of risk assessment for teams integrating ESP32 components into their products, enabling proactive mitigation strategies based on verified industry data and official vendor guidance without the need to manually sift through fragmented sources.

Vendor: espressif

CVE IDTitleCVSSSeverityPublished
CVE-2026-55687 ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsing CWE-121 7.5 High2026-07-10
CVE-2026-46532 ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser CWE-125 4.6 Medium2026-06-10
CVE-2026-45542 ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth CWE-122 7.1 High2026-06-10
CVE-2026-45329 ESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service Wrappers CWE-20 7.1 High2026-06-10
CVE-2026-45328 ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers CWE-20 9.3 Critical2026-06-10
CVE-2026-45160 ESF-IDF: Out-of-bounds Read in lwIP DHCP Server Option Parser CWE-125 6.5 Medium2026-06-10
CVE-2026-45541 ESF-IDF: Remote Null Pointer Dereference in WebSocket Server CWE-476 7.5 High2026-06-10
CVE-2026-25508 ESF-IDF Has Memory Safety Vulnerabilities in BLE Provisioning CWE-125 6.3 Medium2026-02-04
CVE-2026-25507 ESF-IDF Has Use-after-free Vulnerability in BLE Provisioning CWE-416 6.3 Medium2026-02-04
CVE-2026-25532 ESF-IDF is Vulnerable to WPS Enrollee Fragment Integer Underflow CWE-191 6.3 Medium2026-02-04
CVE-2025-68474 ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling CWE-787 7.5 -2025-12-26
CVE-2025-68473 ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling CWE-787 6.5 -2025-12-26
CVE-2025-66409 ESF-IDF has an Out-of-Bounds Read in ESP32 Bluetooth AVRCP Command Handling CWE-125 6.5AIMediumAI2025-12-02
CVE-2025-65092 ESP32-P4 JPEG Decoder Header Parsing Vulnerability CWE-125 9.1 -2025-11-21
CVE-2025-64342 ESF-IDF's ESP32 Bluetooth Controller Has an Invalid Access Address Vulnerability CWE-754--AI2025-11-17
CVE-2025-55297 ESF-IDF BluFi Example Memory Overflow Vulnerability CWE-120 7.4AIHighAI2025-08-21
CVE-2025-52471 ESP-NOW Integer Underflow Vulnerability Advisory CWE-191 9.8AICriticalAI2025-06-24
CVE-2024-53845 AES/CBC Constant IV Vulnerability in ESPTouch v2 CWE-327 7.5 -2024-12-11
CVE-2024-28183 Anti Rollback bypass with physical access and TOCTOU attack CWE-367 6.1 Medium2024-03-25
CVE-2022-24893 Espressif Bluetooth Mesh Stack Vulnerable to Out-of-bounds Write leading to memory buffer corruption CWE-787 7.5 High2022-06-25

All 20 known CVE vulnerabilities affecting esp-idf with full Chinese analysis, references, and POCs where available.